CVE-2024-1892 - CVE House
Back to Database
Status published High CVE-2024-1892

ReDoS Vulnerability in scrapy/scrapy's XMLFeedSpider

Vulnerability Description

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the XMLFeedSpider class of the scrapy/scrapy project, specifically in the parsing of XML content. By crafting malicious XML content that exploits inefficient regular expression complexity used in the parsing process, an attacker can cause a denial-of-service (DoS) condition. This vulnerability allows for the system to hang and consume significant resources, potentially rendering services that utilize Scrapy for XML processing unresponsive.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-1892

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

scrapy/scrapy
Vulnerable Versions:
unspecified

Timeline

Official Publish: February 28th, 2024
Last Modified: August 11th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)